PT-2026-56383 · Libxfont2+2 · Libxfont2+2

CVE-2026-56001

·

Published

2026-07-08

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libXfont2 versions prior to 2.0.8
Description A heap-based buffer overflow exists in the BitmapScaleBitmaps() function. The issue is caused by an integer overflow where a 32-bit size calculation wraps, resulting in an undersized heap allocation and subsequent out-of-bounds writes. An attacker with access to the X Server can trigger this by providing crafted font bitmap data, potentially leading to arbitrary code execution within the X server process and takeover of the display server context.
Recommendations Upgrade libXfont2 to version 2.0.8.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47079
ALSA-2026:47084
ALSA-2026:47103
AZL-92081
CVE-2026-56001
ECHO-FE44-FA4E-C5AA
OESA-2026-3055
OPENSUSE-SU-2026:11233-1
OPENSUSE-SU-2026:21284-1
RHSA-2026:47079
RHSA-2026:47084
RHSA-2026:47103
RHSA-2026:51058
RHSA-2026:51059
RHSA-2026:51060
RHSA-2026:51061
RHSA-2026:51062
RHSA-2026:51063
RHSA-2026:51066
RHSA-2026:51067
SUSE-SU-2026:22614-1
SUSE-SU-2026:2793-1
SUSE-SU-2026:2794-1
USN-8560-1
ZDI-26-406

Affected Products

Rocky Linux
Ubuntu
Libxfont2